Tawk.To Live Chat Security & Risk Analysis

wordpress.org/plugins/tawkto-live-chat

(OFFICIAL tawk.to plugin) Instantly chat with visitors on your website with the free tawk.to chat widget. Website: http://tawk.to

100K active installs v0.9.3 PHP 5.6+ WP 2.7+ Updated Jan 14, 2026
ai-chatchat-widgetfree-live-chattawktawk-to
99
A · Safe
CVEs total1
Unpatched0
Last CVENov 8, 2021
Safety Verdict

Is Tawk.To Live Chat Safe to Use in 2026?

Generally Safe

Score 99/100

Tawk.To Live Chat has a strong security track record. Known vulnerabilities have been patched promptly.

1 known CVELast CVE: Nov 8, 2021Updated 2mo ago
Risk Assessment

The tawkto-live-chat plugin version 0.9.3 presents a mixed security posture. While it demonstrates good practices such as using prepared statements for all SQL queries and having no critical or high severity taint flows, there are significant concerns regarding its attack surface. The plugin exposes two AJAX handlers without authentication checks, making them prime targets for unauthorized access and potential manipulation. Additionally, only 54% of output is properly escaped, leaving room for cross-site scripting (XSS) vulnerabilities in certain scenarios.

The vulnerability history reveals a past high severity issue related to missing authorization, which aligns with the current findings of unprotected AJAX endpoints. The lack of currently unpatched vulnerabilities is a positive sign, suggesting that previous issues have been addressed. However, the pattern of past authorization-related vulnerabilities, combined with the present unprotected entry points, indicates a recurring weakness in how the plugin handles user access control.

Overall, while the plugin avoids critical code-level flaws like raw SQL or dangerous functions, the unprotected AJAX handlers are a notable risk. The historical trend of authorization flaws further emphasizes the need for careful review and hardening of these entry points. This version shows improvement in some areas but still requires attention to its access control mechanisms to reduce its overall risk profile.

Key Concerns

  • AJAX handlers without auth checks
  • Unescaped output detected
  • Past high severity vulnerability (Missing Authorization)
Vulnerabilities
1

Tawk.To Live Chat Security Vulnerabilities

CVEs by Year

1 CVE in 2021
2021
Patched Has unpatched

Severity Breakdown

High
1

1 total CVE

CVE-2021-24914high · 8Missing Authorization

Tawk.To Live Chat <= 0.5.4 - Missing Authorization to Visitor Monitoring & Chat Removal

Nov 8, 2021 Patched in 0.6.0 (806d)
Code Analysis
Analyzed Mar 16, 2026

Tawk.To Live Chat Code Analysis

Dangerous Functions
0
Raw SQL Queries
0
0 prepared
Unescaped Output
13
15 escaped
Nonce Checks
1
Capability Checks
2
File Operations
2
External Requests
0
Bundled Libraries
0

Output Escaping

54% escaped28 total outputs
Attack Surface
2 unprotected

Tawk.To Live Chat Attack Surface

Entry Points3
Unprotected2

AJAX Handlers 2

authwp_ajax_tawkto_setwidgettawkto.php:53
authwp_ajax_tawkto_removewidgettawkto.php:54

Shortcodes 1

[tawkto] tawkto.php:603
WordPress Hooks 9
actionwp_loadedtawkto.php:50
actionadmin_inittawkto.php:51
actionadmin_menutawkto.php:52
actionadmin_enqueue_scriptstawkto.php:55
actionadmin_noticestawkto.php:56
actioninittawkto.php:605
actionwp_footertawkto.php:692
actionwp_footertawkto.php:941
actionplugins_loadedupgrade.manager.php:113
Maintenance & Trust

Tawk.To Live Chat Maintenance & Trust

Maintenance Signals

WordPress version tested6.9.4
Last updatedJan 14, 2026
PHP min version5.6
Downloads4.7M

Community Trust

Rating92/100
Number of ratings140
Active installs100K
Developer Profile

Tawk.To Live Chat Developer Profile

tawkto

1 plugin · 100K total installs

78
trust score
Avg Security Score
99/100
Avg Patch Time
806 days
View full developer profile
Detection Fingerprints

How We Detect Tawk.To Live Chat

Patterns used to identify this plugin on WordPress sites during automated security audits and web crawling.

Asset Fingerprints

Asset Paths
/wp-content/plugins/tawkto-live-chat/assets/css/tawk.admin.css/wp-content/plugins/tawkto-live-chat/assets/js/tawk.admin.js
Script Paths
assets/js/tawk.admin.js
Version Parameters
tawkto-live-chat/assets/css/tawk.admin.css?ver=tawkto-live-chat/assets/js/tawk.admin.js?ver=

HTML / DOM Fingerprints

JS Globals
TawkTo_Settings
FAQ

Frequently Asked Questions about Tawk.To Live Chat